Martinrea International Inc. is a diversified and global automotive supplier,a diversified and global automotive supplier engaged in developing and manufacturing highly engineered, value-added Lightweight Structures and Propulsion Systems. We employ approximately 16,000 skilled and currently operate in 57 locations in Canada, the United States, Mexico, Brazil, Germany, Slovakia, Spain, China, South Africa, and Japan. Martinrea's vision is making lives better by being the best supplier we can be in the products we make and the services we provide.
Our Mission is to make people's lives better by:
- Delivering outstanding quality products and services to our customers.
- Providing meaningful opportunity, job satisfaction, and job security for our people.
- Providing superior long-term investment returns to our stakeholders.
- Being positive contributors to our communities.
Martinrea's success is globally shown through its core sustainable culture. Focused on entrepreneurship, lean manufacturing principles, and the Golden Rule philosophy, Martinrea believes in dignity and respect for its people, communities, customers, and investors. Our strength is in our people, embracing a diverse culture, giving employees opportunities to help grow our footprint and expand product offerings and areas of expertise with discipline, dedication and determination
We invite you to follow your dreams and explore a challenging and rewarding career at Martinrea.
Job Summary:
Senior Information Security Cloud Specialist with 8–10+ years of experience, deep multi-cloud expertise (AWS + Azure), and the ability to drive technical strategy across an IT, Cybersecurity, and other business units. The Senior Specialist will act as DevSecOps lead on security-related projects and technologies and ensure the effective implementation and management of security tools as we continue to improve information security at Martinrea. The Security Specialist will be responsible for providing daily support, IR, and on-call rotation.
Required Education and Experience:
- Bachelor’s degree in Information Security, Cyber Security, Computer Science, or equivalent
- 10+ years of working experience in support of a large-scale, mission-critical enterprise security infrastructure
- 5+ years of previous experience in SecOps, DevSecOps, Cloud Security, Threat Detection & Response, or software development with a strong focus on security tool onboarding and optimization
- 5+ years of working experience with security tools and technology (Defender, Intune, IAM, Vulnerability Management, DLP, and others)
- Deep subject matter expertise with security engineering best practices for subjects such as CVSS, EPSS.
- Design, implement, and maintain security measures for our cloud infrastructure, including VPCs, security groups, IAM roles, and access controls
- Expertise across AWS and Azure security
- Experience with CSPM/CNAPP platforms (Wiz, CrowdStrike, Defender, etc.)
- Experience with AI/ML platforms and cloud-based AI services
- Expert in cloud-native security controls (IAM, KMS, VPC security, encryption, logging, and monitoring).
- 5+ years of experience with MS O365, Azure security, MFA, and MDM are a must
- Deep knowledge and experience with Email Security
- Stay current with cloud security trends, emerging threats, and best practices, ensuring configuration guidance remains accurate and relevant
- Knowledge of security industry standards and certification frameworks such as ISO 27001, SOC2, CSA CCM, NIST, PCI DSS, etc.
- Preferred to have: CCSP, Azure Security Engineer, AWS Security Specialty, and CISSP
Responsible For the Following Essential Functions:
- Lead CNAPP architecture & rollout across multi-cloud and Hybrid solutions, including integration patterns and operationalization design.
- Perform security assessments and audits of our infrastructure, identifying and mitigating security gaps and weaknesses
- Implement and maintain security controls across AWS/Azure, focusing on EKS/AKS cluster security, EC2 hardening, and cloud-native protection
- Investigate potential security incidents and serve as the initial incident responder
- Harden our cloud-native environments (AWS, Azure) by introducing secure-by-default designs and features into network, tooling, and processes
- Drive the design and implementation of Zero Trust architectures, including identity-based perimeters, mTLS, network segmentation, and least-privilege access controls
- Monitor and analyze logs, events, and metrics to identify security incidents, potential breaches, and emerging threats
- Represent DevSecOps to leadership, audit (internal and external), and regulators on technical questions
- Define and publish Security Reference Architectures and reusable patterns (secure-by-design) for engineering adoption across platforms and products. Partner with platform engineering / DevSecOps teams to integrate scanning and controls into CI/CD (e.g., Terraform Cloud, GitHub Actions, Azure DevOps), including risk decisions and exceptions
- Embed security into the full software development lifecycle through scalable guardrails, automated testing frameworks, and developer-facing documentation.
- Develop required documentation to help operationalize and automate technologies in close coordination with security operations to ensure compliance requirements are met
- Continuously identify areas needing improvement, create action plans, and execute to implement changes on time
Work Environment:
- Hybrid (3 days in Office)
Physical Demands:
- Constant communication with employees, peers, and leadership
- Overtime as required
Other Duties:
- This job description is not designed to contain a comprehensive list of duties and responsibilities required for this job. Duties and responsibilities may change at any time with or without notice
Disclaimer:
This job description does not constitute a contract of employment. The Company may exercise its employment at will right at any time.